Cyberattacks Disrupt Two Oil Tankers Bound for Texas
The US Coast Guard and FBI boarded two oil tankers last month after cyberattacks disrupted their voyages. Investigators found evidence of a malicious cyber actor on one vessel, though they have not publicly linked the incidents to Iran.

Two oil tankers bound for Texas were boarded by US Coast Guard and FBI personnel in August after cyberattacks disrupted the vessels during their voyages. The incidents have prompted an ongoing investigation into potential state-sponsored activity.
According to a CBS News report citing US officials, one of the ships was the Liberian-flagged crude tanker VL Prosperity. It left Egypt on August 1 en route to Galveston, Texas. Iran's Mehr News Agency reported the cyberattack occurred on August 7 as the tanker passed through the Strait of Gibraltar.
Citing a crew member, the Iranian outlet alleged the intrusion reached the engine room. Hackers reportedly slowed coolant flow, raised engine speed, and interfered with fuel delivery. The attackers also allegedly accessed navigation and cargo systems and cut off the ship's communications for roughly 30 hours.
Investigation and Boarding
One day after Mehr's report, a team including Coast Guard cyber specialists, law enforcement, a vessel inspector, and FBI Cyber Action Team members boarded the VL Prosperity. They spent four days aboard the vessel. The Wall Street Journal reported that a second ship was boarded on August 24. Both vessels were boarded after they arrived in the Gulf of Mexico.
The Coast Guard has not publicly linked the incident to Iran. Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, told reporters that investigators did find evidence of a malicious cyber actor after reviewing the vessel's IT and other onboard systems. She noted that nothing uncovered during the inspection suggested the tanker was unsafe to operate.
Grable said this was one of an estimated 40 to 50 similar boardings the Coast Guard's Cyber Protection Team has carried out over the past year.
Assessing the Cyber Threat
Quinton DuBose, a former Coast Guard cyber official, pushed back on the idea that hackers could seize full command of a supertanker. He argued the more realistic risk is an attacker degrading enough individual systems to make safe operation difficult. Investigators are still working to determine whether the two tanker incidents are connected and whether Iran or another state actor is responsible.
DuBose urged caution around the Iranian coverage. He noted that Iran-linked actors have a history of overstating their cyber capabilities.
Maritime Cybersecurity Vulnerabilities
The incident comes just days after the US Coast Guard announced a dedicated Office of Maritime Cybersecurity Policy. This office will serve as its central authority for developing and implementing policies governing the cyber safety and security of the marine transportation system.
The cybersecurity community has long warned that the maritime sector's reliance on aging, unmanaged OT systems, satellite communications, and connected IoT devices leaves both vessels and ports dangerously exposed. Attackers can exploit WiFi, HF radio, and SATCOM links, or simply an infected USB stick, to gain access.
A successful compromise could potentially grant remote control over a ship's throttle, rudder, or navigation systems. Beyond ransomware, which has already disrupted shipping operations, experts point to more severe scenarios. These include GPS spoofing, AIS manipulation to disguise a vessel's true location, or deliberately running a ship aground to block a critical waterway.
Given that roughly 80% of global goods move by sea, a targeted attack could trigger billions of dollars in losses and cascading supply shortages.





